LWA-2026-5624 MAL-2026-10602 ↗ confirmed malware

@public-for-cdao/config@99.99.99

Malicious code in @public-for-cdao/config (npm)

Analysis

This package is a dependency-confusion stub published under a scoped name with a synthetic 99.99.99 version. Its package.json runs a postinstall hook (node recon.js) that executes automatically on install. The script harvests reconnaissance about the host (hostname, OS, architecture, username, working directory) and then collects a wide range of CI/CD and cryptocurrency secrets from environment variables, including GitLab CI job/registry/deploy tokens, GitLab access/API tokens, SSH and deploy private keys, AWS access keys and session tokens, database and Redis URLs/passwords, wallet private keys, mnemonics and seed phrases, Infura/Alchemy API keys, npm tokens, Slack/Discord tokens, RPC URLs, and container-registry credentials. It additionally reads common .env files across the filesystem (including paths under /app, /root, and /home/gitlab-runner) and extracts any lines containing key/secret/token/password material, and enumerates CI build directories. The collected data is serialized to JSON and exfiltrated over HTTPS (with TLS verification disabled) to two external collector endpoints, and a copy is written to a temp file. The package provides no legitimate functionality.

analyzed by
Leitwacht
first seen
Jun 17, 2026, 04:12 AM
analyzed
Jun 17, 2026, 04:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.